Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-4969

Опубликовано: 21 мая 2025
Источник: debian
EPSS Низкий

Описание

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsoup3fixed3.6.5-2package
libsoup3no-dsabookwormpackage
libsoup2.4fixed2.74.3-11package
libsoup2.4no-dsatrixiepackage
libsoup2.4no-dsabookwormpackage

Примечания

  • https://gitlab.gnome.org/GNOME/libsoup/-/issues/447

  • https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/467

EPSS

Процентиль: 32%
0.00124
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
7 месяцев назад

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).

CVSS3: 6.5
redhat
7 месяцев назад

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).

CVSS3: 6.5
nvd
7 месяцев назад

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).

CVSS3: 6.5
msrc
4 месяца назад

Libsoup: off-by-one out-of-bounds read in find_boundary() in soup-multipart.c

CVSS3: 6.5
github
7 месяцев назад

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries (out-of-bounds read).

EPSS

Процентиль: 32%
0.00124
Низкий